---
id: CVE-2025-28197
aliases:
  - GHSA-445m-27cf-gr3x
  - PYSEC-2026-1281
title: Crawl4AI SSRF vulnerability
summary: Crawl4AI SSRF vulnerability
severity: medium
vendor: crawl4ai
product: crawl4ai
ecosystem: pip
affected:
  - crawl4ai <= 0.4.247
published: '2025-04-18'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-445m-27cf-gr3x'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-28197'
  - url: 'https://gist.github.com/AndrewDzzz/f49e79b09ce0643ee1fc2a829e8875e0'
  - url: 'https://github.com/unclecode/crawl4ai'
tags:
  - osv
  - pip
epss: 0.00365
epssPercentile: 0.27598
ingestedAt: '2026-07-08T18:25:45.245Z'
---

## Overview

Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.

## Affected packages

- `crawl4ai <= 0.4.247`

## Remediation

Refer to the advisory for the patched release.
